tj-actions
Security Risk Profile
Security Risk Score
Comprehensive risk assessment based on 12 vulnerabilities, EPSS scores, exploitation status, and remediation availability.
📅 Data spans from December 4, 2023 to present
Threat Assessment
Severity Distribution
Exploit Likelihood
Age Distribution
Common Weaknesses (CWE)
Most Affected Products
Recent Vulnerabilities
See more →tj-actions/branch-names Contains Command Injection Vulnerability
That massive GitHub supply chain attack? It all started with a stolen SpotBugs token
Recent GitHub supply chain attack traced to leaked SpotBugs token
Coinbase was primary target of recent GitHub Actions breaches
tj-action/changed-files GitHub action was compromised
GitHub Action hack likely led to another in cascading supply chain attack
Separate supply chain attack tied to 23K pwned GitHub repos
GitHub supply chain attack spills secrets from 23K projects
tj-actions/changed-files GitHub Action Embedded Malicious Code Vulnerability
GitHub Action tj-actions/verify-changed-files is vulnerable to command injection in output filenames
Monitor tj-actions in Real-Time
Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.